CRX | October 13-15, 2026 | Up to 17 CPEs | In-person & virtual options available | Register Now!

Customers
Login
Optro's logo

August 12, 2026 11 min read

The agentic audit era: What CAEs must rethink now

Richard Chambers avatar

Richard Chambers

Agentic AI is already changing how work gets done — including within internal audit. Until recently, internal auditors used AI mostly to draft and summarize. Now, agentic AI is being enabled to plan, decide, and act on its own. Of course, this evolution is also happening across the wider business.

Organizations are facing pressure to adopt agentic AI, and they’re eager to believe the value claims. However, the agentic era introduces countless risks, both known and unknown. Organizations should address key questions around AI agent governance before rushing to implement, but many are forging ahead without building these critical foundations.

Internal audit must bring its controls, processes, risk management, and audit expertise to bear to help businesses adopt and manage agentic AI responsibly. CAEs need to ensure their people, processes, and judgment are ready for the reality of agentic AI before it fully arrives. That begins with understanding how the agentic era will permanently alter the risk and control landscape — and internal audit itself. Here are three things CAEs need to rethink now to prepare for the agentic era.

1. Agentic AI requires new internal controls — and organizations aren’t ready

AI governance continues to lag adoption: A 2026 Optro survey found that only 18% of organizations have active mitigation covering most or all identified AI-related risks. Agentic AI increases the stakes. Organizations are already experimenting with agents, and most plan to deploy them in relatively short order. A 2026 Deloitte study found that 74% plan to deploy AI agents within two years, but only 21% have mature governance to oversee them.

The reality: Most organizations aren’t ready to deploy AI agents. Agents require new internal controls and monitoring mechanisms most businesses don’t yet have in place — let alone understand. Further, existing processes, controls, and governance structures often exacerbate the problem (e.g., siloed data, distributed or unclear ownership, policy-based controls, lack of continuous monitoring).

Existing governance wasn’t built for AI. It must be rebuilt. The agentic age will see AI move from the margins to routinely perform autonomous actions in core business operations. AI agents will make decisions before humans review them, introducing serious risks. How will those agents be governed? As organizations navigate the new controls agentic AI requires, be clear:

  • Accountability must always tie back to humans. New accountability frameworks require robust governance ensuring clear ownership, auditability, explainability, transparency, security, and reliability.
  • Agentic AI outputs only become usable when every action, source, and conclusion can be reviewed and defended. As The agentic AI playbook for internal audit explained, reviewability and auditability require strict logging to record every action performed, every file read, and every conclusion reached, all tied back to source evidence.
  • Controls should never be assumed. Agentic AI technologies embed some controls, but organizations must ensure effective guardrails around human review, activity logging, what agents can access and execute, how that information is maintained, how exceptions are escalated, how sign-offs are owned and documented, and more.
  • Continuous auditing is essential. In the agentic era, retrospective auditing and periodic reviews are inadequate. Effective governance requires:
    • Continuous, automated auditing that responds dynamically to risk indicators
    • Frameworks for assessing and auditing agent behavior
    • Defensible documentation and evidence trails
    • Audit plans accounting for the new risks AI agents create

2. “Agent washing” is an emerging risk organizations must prepare for

Business leaders are eager for AI agents to deliver the game-changing results vendors promise (e.g., competitive advantage, product innovation, cost savings). Unfortunately, there’s a very real risk that “AI agents” may not deliver the anticipated ROI.

Internal audit must prepare organizations for the risk of “agent washing,” the practice of rebranding basic AI or generative AI features (e.g., RPA, chatbots, AI assistants) as agentic AI. (Genuine agents follow a defined script and rules-based system to perform multiple steps toward a goal, adapting to changing conditions without human direction.)

Agent washing is alarmingly widespread: In mid-2025, Gartner estimated that of the thousands of vendors claiming agentic capabilities, only ~130 offered true agentic AI. Agent washing also happens internally, as business leaders feeling pressure to adopt AI may more readily believe employees promising agentic capabilities. Leaders may take action or make investments (e.g., staff reductions, purchases, pilots) based on this information — but in many cases, “agentic” capabilities won’t fit the definition or deliver the hoped-for results.

  • If your organization describes its solutions or services as agentic AI, verify those claims. Don’t wait for a customer, investor, or regulator to uncover the discrepancy.
  • Work with procurement, IT, and AI governance teams to detect/prevent agent washing, defining and documenting what qualifies as an agent, testing system adaptation, and requiring vendors and internal teams to provide evidence (e.g., model details, architecture documentation, live demos using never-before-seen inputs).
  • Set expectations that effective AI agent governance must come first. Even the best agentic AI technology needs effective guardrails to deliver value. We must start by building the governance structures, accountability frameworks, and operational discipline required to support responsible, scalable use of agentic AI.
  • Consider auditing AI strategy. Leadership may be overstating agentic AI capabilities or strategy. Workplace Intelligence research found that 75% of executives admit their AI strategy is “more for show” than actual internal guidance, with 39% lacking a formal plan to use AI tools to drive revenue.

3. Core audit skills must integrate practical AI acumen

To assist with all of the above, internal auditors must develop the practical AI acumen to review, validate, and govern agentic AI outputs.

Fortunately, we’re starting from solid foundations: internal audit’s innate curiosity, critical thinking abilities, and independent, objective, evidence-based perspective. What’s new is the imperative not only to analyze, interpret, and communicate the nuances of agentic AI outputs, but to challenge and validate them. We must ask the right questions to help organizations measure, monitor, and strengthen governance in the agentic era. Accordingly:

  • CAEs must proactively educate themselves and their teams about AI agents and governance. That includes developing and communicating a clear vision for how internal audit’s scope, skills, processes, and workflows must change.
  • Auditor judgment — informed by practical AI acumen — becomes paramount. Only humans decide which questions matter and what the answers mean. Internal audit can provide a trusted, context-informed, critical assessment of AI outputs. Protiviti calls this “risk and decision intelligence,” providing business leaders with “timely risk context, grounded in independent judgment, at or before the moment decisions are made.”
  • Internal audit must redefine its value. Agentic AI will take on much of the evidence collection, testing, and documentation work that has been our bread and butter. To keep providing relevant value, we must:
    • Rethink our processes, workflows, controls, and accountability frameworks.
    • Adapt talent strategies to develop more multidisciplinary skill sets (e.g., AI, analytics, cybersecurity, behavioral analysis) and strengthen our “human edge.”
    • Provide the AI assurance and advisory services our organizations urgently need.

The agentic era will redefine assurance

Developing the practical AI acumen that enables internal auditors to govern, review, validate, and challenge AI agents will expand the traditional concept of assurance. The important distinction is that assurance is no longer backward-looking (hindsight), evaluating controls and compliance, and validating performance after the fact. Rather, assurance becomes real-time and forward-looking (insight and foresight), helping our organizations govern and assess AI outputs — determining what to trust and what to question.

The agentic era is an open invitation for internal audit to definitively shed its “corporate police” image for good, taking on the mantle of trusted advisor. As agentic AI permanently alters the risk and control landscape, we can embrace this opportunity to permanently alter our role.

About the authors

Richard Chambers avatar

Richard Chambers, CIA, CRMA, CFE, CGAP, is the CEO of Richard F. Chambers & Associates, a global advisory firm for internal audit professionals, and also serves as Senior Advisor, Risk and Audit at Optro. Previously, he served for over a decade as the president and CEO of The Institute of Internal Auditors (IIA). Connect with Richard on LinkedIn.

You may also like to read

colleagues looking at a laptop
Internal Audit

Agentic AI in internal audit: which controls should you automate first?

LEARN MORE
colleagues collaborating on sticky notes
Internal Audit

The SEC just named its financial reporting watchdog. Is your CFO ready?

LEARN MORE
Krista Moller at Valneva
Internal Audit

How Valneva gave its SOX program a shot of efficiency

LEARN MORE

Discover why industry leaders choose Optro

SCHEDULE A DEMO
upward trending chart
confident business professional